Back
CVE-2004-2253
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| netwin | surgeldap | 1.0d |
| netwin | surgeldap | 1.0e |
| netwin | surgeldap | 1.0g |
GitHub Security Advisory GHSA-px7h-r23j-7cx7
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote...
References (8)
- http://members.lycos.co.uk/r34ct/main/SurgeLDAP%201.0g.txt Exploit, Vendor Advisory
- http://secunia.com/advisories/11343 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/10103 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15851
- http://members.lycos.co.uk/r34ct/main/SurgeLDAP%201.0g.txt Exploit, Vendor Advisory
- http://secunia.com/advisories/11343 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/10103 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15851
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
7.10%
Top 6% most likely to be exploited
Threat Score
22.1 / 100
Data Sources
NVD
EPSS
GitHub